Skip to content
New issue

Have a question about this project? Sign up for a free GitHub account to open an issue and contact its maintainers and the community.

By clicking “Sign up for GitHub”, you agree to our terms of service and privacy statement. We’ll occasionally send you account related emails.

Already on GitHub? Sign in to your account

security vulnerability #3614

Closed
tharun-d opened this issue May 24, 2023 · 2 comments
Closed

security vulnerability #3614

tharun-d opened this issue May 24, 2023 · 2 comments

Comments

@tharun-d
Copy link

Description

this is security vulnerability, can't say much about what tool we are using to check security issues in our repo.
but the tool is showing some issues with HIGH status

security vulnerability
Gin-Gonic Gin contains a reflected file download attack that sets the Content-Disposition header of a response when the filename is derived from user-supplied input. A remote attacker could leverage this to allow specially crafted files to be downloaded from a trusted domain.

How to reproduce

not sure

Expectations

vulnerability should resolve

Environment

  • go version: 1.20
  • gin version (or commit ref): 1.19
  • operating system: linux we use docker
@tharun-d
Copy link
Author

dup of #3555

@vitordm
Copy link

vitordm commented May 29, 2023

any news about that?

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment
Labels
None yet
Projects
None yet
Development

No branches or pull requests

2 participants